Privacy
What notch.fm knows about you
This is a description of what the app actually does with your data, written from the code that does it. It is deliberately specific, including about the parts that are not flattering.
Last reviewed 15 September 2026
notch.fm, Apple Music and Spotify#
notch.fm is an independent project. It is not affiliated with, endorsed by, sponsored by or connected to Apple or Spotify, and nothing on this site is their product or speaks for either of them.
You need neither of them to use it. An account with no music service connected can search, rate, tag, write notes, build playlists and use every social part of the app, and this page describes that account as much as any other. Connecting a service adds two things on top: playback, and the library you already have.
Apple Music and Spotify are the two services this app is built for, and you can be connected to one at a time, or to neither. No view in this app puts one service’s catalogue next to another’s. Which of the two you can actually connect today is shown on the home page and in Settings, because it changes.
Whichever you connect, notch.fm has no player of its own. When you press play here it sends a command to that service’s own app or web player, already signed in on one of your devices, and the service plays the audio, counts the stream and pays the rights holders exactly as it would if you had pressed play there. It also means playback control follows their rules rather than ours: Spotify requires Premium for it, and Apple Music requires a current subscription. notch.fm never sees or asks for your password at either service.
What a service does with your data is governed by its own policy, not this one. See Spotify’s privacy policy and Apple’s privacy policy. This page only covers what notch.fm does.
If you connect Spotify: what it reads, and what each one is for#
Connecting the app opens Spotify’s own permission screen. It asks for the permissions it uses and no others - and it does ask for write permissions, because saving a like and building a playlist are writes. Each row below is a permission, the Spotify data it covers, and the part of notch.fm that would stop working without it. If something is not on this list, the app does not ask for it.
- Library and saved tracks
- Your Liked Songs, with their album and artist metadata. This is the raw material of the whole app: the library page, rating, tagging, sorting, the charts and the stats are all built on the songs you have saved.
- Top artists and tracks
- Two jobs. When you connect, they seed a starting score for songs you have never rated, so the library is not a wall of blanks on day one - and a seeded score is marked as seeded, is never counted as your opinion, and never feeds the community averages. After that they are re-read now and then, cached for a few minutes at a time, to put the songs you actually listen to at the front of the rating queue instead of whatever happens to be alphabetically first.
- Currently playing and playback state
- What is on right now, how far through it is, and which device is active. It is what the Now Playing screen follows, and it is how notch.fm records that you played something so the history and stats pages have anything in them.
- Playback control
- Play, pause, skip, seek and queue, issued only when you press the button on a notch.fm screen. The command goes to Spotify and Spotify does the playing; notch.fm decodes no audio.
- Playlists
- Reading your playlists, including private ones, so notch.fm can show them and use them as a source when you build one here. Creating and editing a playlist happens only when you ask for it, on the playlist you named, and never touches a playlist you did not choose. Like a save, a playlist write Spotify refuses is kept and pushed later rather than lost.
- Search
- Spotify catalogue search, run with your own account, so you can find a song, album or artist that is not in your library yet, open it, rate it or add it to a playlist. Your search text goes to Spotify to answer the search and is not kept as a search history.
- Saving to your library
- The like button writes a song to your Spotify Liked Songs. It happens when you press it, never on its own, and never in bulk behind your back. If Spotify refuses the write, notch.fm keeps it and pushes it when Spotify will accept it, so nothing you did is silently dropped - the screen says which state it is in rather than pretending it landed.
- Account basics
- Display name, avatar, Spotify id, and whether the account is Premium. NOT your Spotify email address: that permission is no longer asked for, because your notch.fm account is its own email address and a connected service must not be able to move it. The Premium flag exists so the app can say plainly that playback control needs Premium instead of failing at you with an unexplained error.
If you connect Apple Music: what it reads#
Apple Music support is being built. Until it appears in Settings, nothing here reads or stores anything from Apple, and there is no Apple credential attached to your account for it to read. This section is written now rather than added later, so that the page is not silent about it in the meantime.
When it is available, connecting opens Apple’s own authorisation screen and returns a token scoped to your music library. notch.fm will read the same things it reads from Spotify and for the same reasons: your saved library and its metadata, because that is the raw material of the whole app; what is playing now, so the history and stats pages have something in them; and your playlists, so it can show them and use them as a source. Playback commands go to Apple’s own player on your device, and as with Spotify this app decodes no audio.
Two differences are worth stating in advance. Apple does not hand over an email address or a display name, so an Apple connection tells notch.fm less about you than a Spotify one does, and your notch.fm account keeps whatever name and address you signed up with. And the token Apple issues expires on its own timetable; when it does, the app asks you to authorise again rather than holding anything open in the background.
What notch.fm never does with any of it#
- No audio is downloaded or stored. Not tracks, not previews, not clips. There is no audio player and no audio file anywhere in this app. Album art is shown from the service’s own image links rather than copied onto these servers.
- No model is trained on it. notch.fm trains nothing, on anybody’s data. Where a third-party model is used it is called through an API under commercial terms that state inputs and outputs are not used to train it, and the exact sends are itemised below.
- Two services are never mixed. Your account is connected to one music service or to none, and no screen in this app interleaves one service’s catalogue or metadata with another’s. Switching services is something you do deliberately in Settings. Combining them is not something this app does at all.
- Your service tokens never reach the browser. They are encrypted before they are stored and are used only by the server, so no page in this app has ever held one. They are not shared with, sold to or sent to any third party, ever.
- Nothing is sold, and there is no advertising. No data broker, no ad network, no audience list, no profile of you sold on to anyone.
Turning it off#
A connection is yours to revoke, and the switch is on the service’s side rather than one this app can hold shut. For Spotify it is spotify.com/account/apps. For Apple Music it is the Apple Account settings on your device. Settings → Music service disconnects from this end, and if you have connected nothing there is nothing here to revoke.
- Revoking takes effect immediately. notch.fm can no longer read your library, see what is playing, control playback or write anything to your account.
- The stored token stops working, because the service stops honouring it. Nothing here can quietly keep reading.
- Any save or playlist edit still waiting to reach the service stops waiting. It stays in your notch.fm library, and it lands there only if you reconnect.
- What you made in notch.fm - your ratings, tags, notes and local playlists - stays in your notch.fm account, so reconnecting picks up where you left off. If you want that gone as well, export it and then delete the account: both are below.
- Saved songs you never touched here are removed five days later. Five rather than immediately for one reason: somebody who disconnects by mistake, or to attach a different account, should not lose anything between two clicks. Reconnect inside those five days and nothing is removed at all. Settings tells you the date.
- Anything you acted on here stays: a song you liked, rated, tagged, put in a playlist, superliked or commented on. That is your record rather than the service's, so the service's clock does not apply to it - and the song stays in your library, not just the score attached to it.
What it stores#
- Your ratings
- The score you gave each song, with a revision history, so a chart can tell a considered change of mind from a mis-tap.
- Your tags
- The genre, mood, vibe, sound and custom tags you put on songs, and any tag names you coined.
- Your library, cached
- Track, album and artist metadata - names, artwork links, release dates, durations - so the app can search and sort without asking a service on every keystroke. Where it came from depends on where you found the song: a connected service, or the public catalogue notch.fm searches when you have connected nothing. Metadata only: no audio, and no artwork files.
- What you played here
- notch.fm counts plays it saw itself while Now Playing was watching. It does not import listening history from any service.
- The social parts
- Your profile, who you follow, comments you post, superlikes, playlists, XP, level and badges.
- Music service tokens
- If you connected one. Encrypted with AES-256-GCM before they touch the database. They are never sent to the browser, so no page in this app has ever held one, and they are never shared with a third party. Disconnecting deletes them.
- Your session
- A signed token in an httpOnly cookie, valid for 30 days. JavaScript on the page cannot read it. See the cookies page.
- Billing
- Your plan and the subscription identifiers attached to it. Card numbers are never sent to notch.fm and are never stored by it.
What leaves this app#
This instance runs Google Analytics and there is no advertising. Analytics records page visits and a small set of named product events, with IP anonymisation on, and sends nothing at all when your browser asks not to be tracked. No event carries your email, your id at a music service, your name, or anything you rated. See cookies for the detail. Beyond that, these services see data, and they see different things:
- Your music service, if you connected one
- Obviously - it is your library, and every playback command, search and write goes to them. Their handling of it is governed by their own privacy policy, not this one. Connect nothing and this row does not apply to you: no music service hears from this app on your behalf.
- Anthropic (smart search)
- When you type a sentence into the search box, that sentence is sent to Anthropic’s API to be translated into a filter. Only the words you typed go - not your library, not your ratings, not your name. The model returns a filter object; your own database does the searching, which is why a hallucinated song title can never reach your results.
- Anthropic (notchbot)
- Asking notchbot a question about your own library is a bigger send, and it should be stated as one: a summary goes with the question - your display name, how many songs you have saved and rated, your average score, how many tags and playlists you have, your level, and your top artists and most-used tags with their counts. Individual songs, your email and your tokens are not included. Nothing sent is used to train a model.
- Ticketmaster
- The Concerts tab looks up tour dates by artist NAME. Opening that tab enrols the artists you have rated highest, and from then on their names are looked up on a schedule. The artist name is all that goes: never your name, never any service id, and nothing that says whose watchlist it came from. If you never open the tab, nothing of yours is enrolled.
- Stripe
- Only if you subscribe. Stripe takes the payment and notch.fm receives the plan status back. Your card details go to Stripe directly and are never sent to notch.fm.
What the server records about every visit#
Every request to notch.fm is written down, the way any web server writes down requests. This is first-party: it stays in notch.fm’s own database, it is not sold, not shared, and no third party is involved at any point. It applies whether or not you have an account, because a request arrives before anybody knows who sent it.
- Your IP address
- Kept for 7 days, then deleted. It is what makes it possible to tell one visitor from another and to recognise a scraper reading the whole catalogue. After 7 days only counts remain, and counts identify nobody.
- The page, the result and how long it took
- Which page, whether it worked, and the time it took to answer. Identifiers in a path are replaced before anything is counted, and the query string is dropped entirely - so what you typed into a search box is never in this.
- Your browser's user-agent, and where you arrived from
- The browser string, and the site that linked you here if there was one. Used to tell people apart from crawlers, and to know which links actually bring anybody.
- Page views and time on page
- If your browser reports it: which page, and how long the page was actually visible. Kept for 90 days. Switching tabs stops that clock. Sent only if you have not turned on Do Not Track or Global Privacy Control - if you have, nothing is sent at all.
- Counts, kept indefinitely
- Requests per hour, per page, per country, per source. No address, no user-agent, nothing that identifies a person or a visit. This is what remains after the 7 days, and it is what the word “analytics” means here.
If a caller behaves like a scraper, that address can be blocked. That decision is always made by a person: nothing on notch.fm bans an address automatically, and the database itself refuses to record a block that nobody authorised. If you think you have been blocked in error, write to us and say so.
If you have an account, deleting it removes the link between you and these records: the rows stay, your account is no longer attached to them, and the counts survive because they identify nobody.
What other people can see#
- Your profile, and anything you publish - comments you post and playlists you choose to make public.
- Community averages, only if you opt in. Settings → Preferences has a “Contribute to community averages” switch. While it is on, the ratings you set yourself are added into the aggregate scores behind the charts. Only your own ratings ever count - never the ones the app seeded for you - and the aggregate is a running total with no link back to who contributed what. Turn it off and your contribution is subtracted again.
- Nothing about your music service account, unless you publish it. Your email, your id at that service and what you are playing right now are not on your public profile. Settings → Privacy chooses how findable you are at all, down to a mode where nobody can open your profile but you.
What the paid plan buys#
Premium buys notch.fm’s own features and nothing else: it is not a way to pay for music. It lifts the caps this app imposes - unlimited rated songs and tags, unlimited playlists, publishing them, posting comments, the badge and level track, more superlikes, and uncapped smart search - and that is the whole of it.
It unlocks nothing on Apple Music’s or Spotify’s side, does not include or replace a subscription to either of them, and gives you no access to any music you did not already have. Music, playback and streams stay entirely with whichever service you use and with your own account there. Paying here changes nothing about what that service lets you do.
Said the blunt way round: if you pay notch.fm and nothing else, you get every notch.fm feature and no music. The rating, tagging, searching and organising are what is for sale here. The listening is not ours to sell.
Getting it all back#
Settings → Your data → Export everything (JSON) gives you one file containing every rating and its revision history, every tag you applied, every like and playlist held locally, and the track metadata needed to read them. It is not behind the paywall and never will be - the ratings are the irreplaceable part, and an export you have to pay for is a hostage.
Deleting it all - including what survives#
Settings → Danger zone → Delete account. You type a confirmation phrase, and it is a hard delete inside a single transaction: your account, your encrypted music service tokens, your ratings and their revisions, your tags, your play history, your sync state, your profile and your subscription all go. There is no soft delete, no thirty-day grace period, and no undo. Export first.
Two things deliberately do not go, and you should know before you press it:
- Comments are tombstoned, not removed. A comment stops being attributed to you, but the text stays where it is. Deleting an account should not silently delete half of other people’s conversations. Delete the comments you care about before you delete the account.
- A tag name other people use stays. If you coined a tag and nobody else has ever used it, it is deleted with you. If other people have adopted it, the tag survives - with no link to you - because removing it would strip it off their songs too.
One more, for completeness: if you contributed to community averages, the totals your ratings fed keep those numbers. They are sums and counts with no identity attached, and there is no row left that says they were ever yours.
Deleting your notch.fm account does not touch your music service account or anything in it. Songs you liked and playlists you built through notch.fm were written to your library there and stay there; they are yours, and this app removing them on the way out would be vandalism. Revoke access separately: Spotify at spotify.com/account/apps, Apple Music in your Apple Account settings.
Your rights over any of this#
Wherever you live, you can do all of these, and most of them without asking anybody:
- See it. The export above hands back everything this app holds about you, as JSON, free, and not behind the paywall.
- Correct it. Every rating, tag and profile field is editable in the app. There is nothing to write in about.
- Delete it. Settings deletes the account and what it holds. What survives and for how long is spelled out above rather than summarised.
- Take it elsewhere. The export is a plain format, not a proprietary one, precisely so it can be read by something that is not notch.fm.
- Object, or withdraw a consent. Disconnect a music service, turn off community averages, or email us. Nothing here depends on you having agreed to anything optional.
If you are in the UK or the EU, those are your UK GDPR and GDPR rights and this is how they are honoured - through the app where possible, because a right you have to request is a right you mostly do not use. Email support@notch.fm for anything the app cannot do, and you have the right to complain to your local data protection authority if we get it wrong.
Nobody under 16#
notch.fm is not for children and does not knowingly collect anything from anyone under 16. That age is the reason there is no parental consent machinery here: below it, nobody should be signing up at all.
If you are a parent and believe your child has an account, email support@notch.fm and it will be closed and deleted without argument.
Who runs this, and questions#
notch.fm is built and run by Sean Brill, a sole proprietor based in New Jersey, United States. There is no company behind it, and none is claimed. For data-protection purposes that person is the data controller: the one who decides what is collected and why, and the one answerable for it.
Privacy questions go to support@notch.fm, or through the contact page if you would rather not send email - it takes a message and an address to reply to without needing an account.
Contact lists what you can do yourself and what to include if something here does not match what you are seeing. The cookies page covers what is stored in your browser rather than on the server, and terms covers the deal itself.